Microsoft extend deadline for Basic Authentication

I just found out today that Microsoft have extended their deadline for Basic Authentication support from September 2025 to 30th April 2026. This gives us more time to allow some platforms to catch up. Perhaps there has been some pressure from some of our partners providing software globally because they need more time to prepare. I was surprised to learn that Xero, our accounting software provider, had no plans yet to address this. If they do not enable a facility to use our own domain to send our invoices to our customers, we will have a problem. Kopage, the website design software used for some of our customers’ websites have no immediate plans to make changes to how their contact forms will cope with Modern Authentication.

Faced with this uncertainty, I am now in the process of upgrading Kopage customers to the WordPress platform for greater assurance that website contact forms will actually reach my customers’ inboxes. There is an assumption, quite rightly, that this should happen anyway as part of our website hosting service. This is why we are offering the website upgrade free of charge to all our web hosting clients and including any addtional charges in our £150+/per month Managed SEO Packages >>

Further research on Microsoft’s decision to move the deadline

Microsoft moved the deadline for the end of basic authentication support to 2026 due to a combination of factors, including the need to provide more time for customers to migrate to modern authentication methods and the recognition that some customers, particularly those with specific configurations or exceptions, might still be using basic authentication. Additionally, while basic authentication has been deprecated for many protocols, some scenarios, like specific SMTP AUTH usage, still required more time for complete transition. 

Here’s a more detailed breakdown:

  • Security Concerns: Basic authentication is a less secure method of authentication, relying on sending usernames and passwords with every request. This makes it vulnerable to credential theft, especially if not protected by TLS. 
  • Customer Readiness: Microsoft acknowledged that many customers were not yet ready to transition to modern authentication methods, despite previous deadlines. Some were unaware of the change, while others simply hadn’t completed the necessary steps to upgrade their systems. 
  • Specific Use Cases: Certain scenarios, such as the use of basic authentication with SMTP AUTH (for sending emails from applications), were more complex to migrate and required additional time. 
  • Extended Support: Some products, like SharePoint Server Subscription Edition, will continue to support basic authentication until July 14, 2026. 
  • Gradual Rollout: Microsoft has taken a phased approach to deprecating basic authentication, disabling it for new tenants first, then for existing tenants with no recorded usage, and finally for all tenants. 

Ultimately, the decision to move the deadline to 2026 reflects Microsoft’s commitment to improving security while recognizing the practical challenges some customers face in transitioning to modern authentication. I think Microsoft underestimated the scale of the work involved and the challenge of getting the message out in time. My experience so far has shown that most IT support companies were not aware of the 2025 deadline, let alone the new 2026 deadline announced only last month. It is only through my own support network that this update has come to my attention and it is my professional duty to share it with you.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top